Privacy policy
Last updated: 17 August 2026
The German version of this page is the legally binding one.
AbiHive is used by school cohorts that consist largely of minors. This policy is therefore written to be readable without prior knowledge, and it names every point at which data leaves our system.
1. Controller
The controller for processing within the meaning of the GDPR is:
Susanne Vollmann, Am Schießwasen 17, 97447 Gerolzhofen, Germany
Email: hallo@abihive.de
No data protection officer has been appointed; the legal conditions for that are not currently met. For any data protection question, reach us at the address above.
2. The short version
- Without an account and without your consent we measure nothing about you.
- Everything you create in the app is visible to your cohort — not publicly, and not to other year groups.
- “Anonymous” means your name is not shown to your classmates. It is not deleted.
- The servers and the database are in Frankfurt am Main.
- You can download everything we hold about you at any time from your profile, and delete your account yourself.
3. If you only visit the website
When you open our pages your browser transmits technically necessary data, which our server records in log files: IP address, date and time, the address requested, the HTTP status, the volume transferred, the referring page and the browser identifier.
The purpose is operating, stabilising and securing the site. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is an offering that works and is defended against attack. Logs are deleted after 14 days at the latest, unless a specific incident requires keeping them longer in order to investigate it.
4. Hosting
The website, the application and the database run on Render (Render Services, Inc.) in the Frankfurt am Main region. Render processes the data solely on our instructions; a data processing agreement under Art. 28 GDPR is in place.
Uploaded files — photos, voice recordings, book exports — are stored, depending on configuration, either on the same server or in an S3-compatible object store inside the EU. The legal basis is Art. 6(1)(b) and (f) GDPR.
5. Cookies and local storage
We set no advertising cookies and embed no ad networks. The following are technically necessary:
- Sign-in. After you log in, an access token is held in your browser's local storage so you stay signed in. It is removed when you sign out.
- Language. One entry remembers which language you read the site in.
- Consent state. One entry remembers whether you accepted or declined analytics — otherwise we would ask again on every visit.
No consent is required for this storage (§ 25(2)(2) TDDDG); it is strictly necessary for the service you asked for. For anything beyond that, we ask.
6. Web analytics
On the website we use Google Analytics 4 to measure which pages get used. This happens only after your explicit consent: until you accept in the banner, consent mode is set to “denied”, no analytics cookies are written and no measurement data is transmitted.
What is transmitted: the page path, approximate location at country/city level, device type, and events such as “sign-up completed”. We pass on no names, no email addresses and no content; query parameters are stripped from the URL beforehand so that sign-in and invitation tokens are not sent along.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Transfer to Google LLC in the USA cannot be ruled out; it is based on the EU-US Data Privacy Framework and additionally on standard contractual clauses. The legal basis is Art. 6(1)(a) GDPR and § 25(1) TDDDG.
You can withdraw your consent at any time with effect for the future — via “Analytics settings” in the footer of every page.
Our own, anonymous measurement. Separately from the above, our own server counts how quickly pages load for you, which pages are opened, how long a page was visible, how far down it was scrolled and whether it was used at all — and how often individual steps before sign-in are opened and completed, for example how many people open the registration form and how many submit it.
No personal reference arises from this: what is stored is a measurement or a name from a fixed list, and the hour it arrived. No user id, no session, no cookie, no IP address. These data cannot tell anyone who you are and are never joined to your account. They do not leave our server.
The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in a working, fast service. Because no cookies are set and no information is read from your device, no consent is required; this measurement therefore also runs if you did not agree to the web analytics above.
7. Account, sign-in and cohort membership
For an account we process your name, email address, a hashed password (if you set one), the school and year group you chose, the time and version of the terms you accepted, and whether your email address has been confirmed. Optionally a profile picture and a phone number. We also keep the day you were last signed in and active — the date only, no time of day and no list of pages visited. From that we work out how many people use the service daily, weekly and monthly. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in knowing whether the service is being used.
There are three ways into an account and all three process the same data: registration with a password, a sign-in link by email (“magic link”), and sign-in via an external provider (Google, Microsoft, Apple, GitHub, Discord, Facebook). In the last case we receive your name, email address and an identifier from that provider; we send no content there. Which providers are offered at all depends on the configuration of your installation.
The legal basis is Art. 6(1)(b) GDPR — without this data we cannot give you an account or access to your cohort.
8. What you create in the app
The whole point of the application is that a cohort collects content together. Depending on which areas your cohort has enabled, we process:
- profile answers, profile photos and — if enabled — a voice recording,
- quotes you write, and quotes you are named in,
- comments you write, and comments written about you,
- photos you upload to the gallery, with filename and timestamp,
- votes in surveys and rankings, and comments on surveys,
- textile selections and orders, book orders, payments,
- likes, badges, committee memberships, event RSVPs,
- free pages, course reports, teacher quotes,
- feedback you send through the feedback function,
- push registrations for your device, if you allowed notifications.
This content is not public. It is visible to the members of your cohort and to your cohort's administrators. We ourselves see it only where support, security or a legal obligation requires it. Whatever ends up in the printed book is seen by everyone who holds that book.
The legal basis is Art. 6(1)(b) GDPR (performance of the usage contract); for areas your cohort explicitly enables and in which you take part voluntarily, additionally Art. 6(1)(a) GDPR.
9. What “anonymous” means
Some areas — comments, the confessions box — allow anonymous contributions. Anonymous here means: your name is not shown to the other members of your cohort. The contribution stays linked to your account in our database. Your cohort's administrators can see the authorship, and so can we in the context of moderation, security and legal requirements.
That is a deliberate decision: without that link, bullying through anonymous posts could not be followed up. Anonymity here protects you from each other, it does not make you invisible.
10. Voice recordings (“This is how you sound”)
If your cohort enables the feature, you can record a short voice message. We store the audio file, its length and the timestamp.
That recording can be played from a QR code in the printed book without signing in. Anyone who scans the code hears it — including people outside your cohort. The link contains a random, unguessable token, but is not otherwise protected.
There is no automatic deletion deadline. A printed QR code cannot be recalled, and an expiry date would silence books that have already been handed out. A recording disappears if you delete it yourself, if moderation removes it, or if your account or your year group is deleted. After that the code shows a notice page instead of the recording.
The legal basis is your consent, Art. 6(1)(a) GDPR, given by recording and saving, and withdrawable at any time by deleting the recording.
11. Notifications
We send emails that are necessary to operate the service — sign-in links, password resets, email confirmation, cohort invitations — and, if you have enabled it, notices about deadlines and news from your cohort. Every non-essential email carries an unsubscribe link.
Sending runs through a provider with a Resend-compatible API (currently Resend, Resend Inc.). Push messages run through the push service of your browser or operating system. If your cohort sets it up and you have stored a phone number, notices can additionally run through the WhatsApp Business Cloud API (Meta Platforms Ireland Limited); with no number stored, that does not happen.
The legal basis is Art. 6(1)(b) GDPR for operationally necessary messages and Art. 6(1)(a) GDPR for everything you switched on in the settings.
12. Book, print, textiles and payments
To print a book we transmit the print file and the delivery address to our print partner Peecho (Peecho B.V., Netherlands). The print file contains the content your cohort put into the book.
For textiles we transmit the design, the sizes and the delivery details to Shirtigo (Shirtigo GmbH, Cologne).
Payments are handled through Stripe (Stripe Payments Europe, Ltd., Dublin). We do not receive payment details such as card numbers; those are entered directly with Stripe. We receive the payment status and the amount.
If a cohort uses AI-assisted design generation, the text prompt entered is transmitted to Recraft (Recraft, Inc., USA). Personal data does not belong in such a prompt; we transmit none of our own accord.
The legal basis in each case is Art. 6(1)(b) GDPR — without that transfer there is no book, no shirt and no payment.
13. Recipients at a glance
- Render Services, Inc. — hosting of the application and database, Frankfurt region.
- Google Ireland Limited — web analytics, only after consent.
- Resend, Inc. — sending transactional email.
- Peecho B.V. — printing and shipping the books.
- Shirtigo GmbH — producing and shipping the textiles.
- Stripe Payments Europe, Ltd. — payment processing.
- Meta Platforms Ireland Limited — WhatsApp notifications, only if configured and with a stored number.
- Recraft, Inc. — image generation, only when the feature is actively used.
- Object storage provider (S3-compatible, EU) — storage of uploaded files.
Data processing agreements under Art. 28 GDPR are in place with every processor. Transfers to third countries occur only as stated above and are based on an adequacy decision or on standard contractual clauses under Art. 46 GDPR.
Beyond that we disclose data where we are legally obliged to — for instance to law enforcement authorities.
14. Retention and deletion
- Account and content: for as long as your account exists.
- Server logs: 14 days at most.
- Analytics data: per the retention settings in Google Analytics, 14 months at most.
- Invoice and order data: ten years, because § 147 AO and § 257 HGB require it.
When you delete your account, your content is deleted or detached from your name. The account record itself is anonymised rather than deleted where transactions subject to commercial and tax retention duties hang off it — Art. 17(3)(b) GDPR expressly permits this. What remains in that case is a record with no name, no email address and no content.
What has already been printed cannot be recalled. See also section 10 on voice recordings.
15. Minors
AbiHive is aimed at graduating cohorts, most of whose members are minors. Under § 4(3) BDSG, a child's consent in relation to information society services is valid in Germany from the age of 16. Anyone younger needs the agreement of their parents or guardians.
We ask parents and guardians to contact us with any questions. On request we provide information about the data stored for a minor's account and delete it.
16. Your rights
- Access (Art. 15 GDPR) — under “Privacy” in your profile you download everything we hold about your account immediately and without being asked why: as a PDF to read or as JSON to pass on.
- Rectification (Art. 16 GDPR) — you change your name, email address and profile yourself.
- Erasure (Art. 17 GDPR) — you delete your account yourself in your profile, within the limits of section 14.
- Restriction (Art. 18 GDPR) and portability (Art. 20 GDPR) — the JSON export exists for exactly this.
- Objection (Art. 21 GDPR) to processing based on a legitimate interest.
- Withdrawal of consent (Art. 7(3) GDPR), at any time and with effect for the future.
An email to hallo@abihive.de is enough for all of it. We answer within the period set by Art. 12(3) GDPR.
17. Right to complain
You can complain to a data protection supervisory authority. The one responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 27, 91522 Ansbach, Germany. You may also approach the authority where you habitually reside.
18. No automated decision-making
We make no decisions with legal effect based solely on automated processing, and we carry out no profiling within the meaning of Art. 22 GDPR.
19. Changes to this policy
When the application changes, this policy changes with it. The version in force is always the one on this page; the date is at the top.